Ransomware payments cratered in 2025, but attacks surged to record highs
2026-03-04T22:49:49Z•5a3cadd5fa5a66558121541f0c5f62fb5933e494defe0bad852c2f13e6a7db40
AI-augmented attacksAnthropic ClaudeCISACisco SD-WANFive EyesFortiGateLazarus GroupMedusa ransomwareShinyHuntersSolarWinds Serv-UUNC2814data-breachextortionpatchingransomwareremote-code-executionsupply-chainvulnerabilities
What happened
A run of high-impact security stories: ransomware payments plunged in 2025 even as attack volume hit record highs, with new and rebranded gangs proliferating. Multiple large data breaches and extortion campaigns were reported (ManoMano subcontractor exfiltration allegedly ~37M accounts; ShinyHunters leaks including Odido and Wynn Resorts; French bank-account database theft). Nation-state and criminal activity continues (UNC2814 spreadsheet-based espionage; North Korea’s Lazarus using Medusa ransomware). Urgent vulnerability advisories and active exploitation featured prominently — Five Eyes on
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 5a3cadd5fa5a66558121541f0c5f62fb5933e494defe0bad852c2f13e6a7db40
- Enrichment time
- 2026-03-04T22:49:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.